GDPR for Small Businesses: What SMBs Need to Know

The General Data Protection Regulation (GDPR) is a piece of legislation heard ’round the world, even though it is a European Union (EU) law. That’s because the law governs how data on EU citizens can be collected, stored, and used by any business or organization in the world, including publishers and website owners. Still, there are many questions about how much — or even if — the law applies to small to medium-sized businesses (SMBs).

So, let’s answer a popular question: “Does GDPR apply to small businesses?” The answer is “Yes.” Small to medium-sized businesses are under the same telescope as large corporations when it comes to GDPR. 

Still, there seems to be some misinformation or misunderstanding by small business owners about their compliance. A 2019 study showed that about half of small businesses in Europe were not compliant with GDPR — one year after the law went into effect. SMBs outside of the EU may be even more in the dark about the law because they don’t believe that the European law can affect them.

If you’re collecting personal data from people in the EU, you fall within the scope of the GDPR’s reach. To make sure your business is compliant, we’ve put together this beginner’s guide to GDPR for small businesses.

GDPR for SMBs: The Basics

Person typing on laptop with GDPR logo overlaid on world map image

Your SMB might seem like small potatoes in the larger scheme of things, but the GDPR still applies. There is somewhat of an exemption for businesses with fewer than 250 employees, but it doesn’t let SMBs totally off the hook.

What this exemption does is curb the requirement under Article 30 that you must keep records of your data processing activities. This applies to organizations with fewer than 250 employees, unless:

“…the processing it carries out is likely to result in a risk to the rights and freedoms of data subjects, the processing is not occasional, or the processing includes special categories of data as referred to in Article 9(1) or personal data relating to criminal convictions and offences referred to in Article 10.”

In other words, if your data processing for EU citizens is frequent, could risk someone’s rights or freedoms, or falls within a special data category listed in Article 9, you’ll still need to keep records.

Furthermore, your SMB may not need to appoint a Data Protection Officer (DPO) like larger businesses that collect data on a large scale do. You can learn more about that requirement in Article 37.

Becoming Compliant

There is no full exemption from GDPR for small businesses, so other areas of the law are ones you’ll need to comply with if you collect data from EU individuals. Even if you own a small blog with visitors from the EU, this could apply to you.

Ensuring compliance from the moment you have your site up and running can save a lot of headache down the line. And once you become compliant, you’ll need to make sure you stay that way. 

With GDPR, compliance mostly means consent. You must collect users’ consent before you engage in activities that use their data, like collecting cookies on your site or adding them to an email list. Offering transparency in the way that you collect data through a detailed privacy and cookie policy is also a must.

For help with getting consent from your visitors, use the ShareThis Consent Management Platform. The tool allows transparency so that your visitors can decide what information they’re comfortable with you collecting. 

Regular Auditing

Keyboard, laptop, tablet, and tablet PC and smartphone on a table with GDPR logo and images on devices

As your business grows, GDPR may affect you differently, particularly if your business hires more than 250 employees. It’s crucial to continuously monitor your business and its compliance through regular auditing because the way in which you collect and process data may evolve.

In addition to auditing your data collection process, you’ll need to consider the data collection processes of third-party services you use. These all collect data in different ways, and it’s up to you to make sure your customers and website visitors know how it works. Be sure to update your privacy policy if you make any changes to the way you or your third-party services collect data.

Pulling in Help

GDPR can be confusing for any size business, but SMBs are at a particular disadvantage if they don’t already work with a legal team that can advise them on compliance with the law. Pulling in help from legal experts can set your business on the right track toward GDPR compliance.

GDPR carries a hefty fine if you’re caught being non-compliant. And the risks are greater for SMBs without the high revenue of larger companies. Currently, the fines are the greater of 2-4% of your annual company revenue or €10-20 million.

Err on the side of caution and seek the help of an attorney experienced in GDPR. Call around to a few of them and take advantage of a free consultation before deciding on the best fit for your business.

Make the process of getting consent from website visitors easier with the ShareThis Consent Management Platform. Get started for free.

About the author
ShareThis

ShareThis website tools, plugins, and apps are used by over 3 million websites to drive consumer engagement and traffic, capturing sentiments of people across the internet. These signals are observed and processed to better understand people, making social data actionable for any business that requires a holistic view of people or customers.

About Us

As a pioneer in the industry, ShareThis has powered human connections through free engagement and growth tools since 2007. Over 3 million publishers leverage ShareThis’ website tools to reach their marketing goals whether they want to amplify their website traffic or social following.